CNCERT warns of FlyLegit: protect hosts from becoming attack nodes
Review remote management, unexpected outbound traffic and recovery on Linux and IoT devices.
Contents of this article
What the notice reports
CNCERT’s September 30, 2026 notice reports joint monitoring with NSFOCUS of FlyLegit spreading to Linux and IoT devices and using them for DDoS. Operators should examine unauthorized outbound activity as well as incoming attacks.
Start with management exposure
Review exposed management services, default accounts, old firmware and neglected edge devices. Assign owners and update paths, restrict access where upgrades are delayed, and plan replacement. Avoid shared management passwords across fleets.
Correlate egress with expected workloads
Compare unfamiliar destinations, idle-time packet bursts and recurring unknown processes with scheduled work. These symptoms alone do not identify FlyLegit; correlate published indicators with host and network evidence.
Recovery must prevent reinfection
Contain unnecessary connectivity and preserve evidence before cleaning or rebuilding from trusted media. Fix the entry weakness, rotate affected credentials and observe egress. Killing a process or protecting the public service alone does not recover a compromised device.
